
Matt Konda -- OWASP Glue
Om avsnittet
Developers need useful findings in their workflow, not another collection of security tools to operate by hand. Matt Konda explains how OWASP Glue grew from that problem: run multiple tools, normalize their output, and make the results usable in a build or development process. He shares his path from software development into AppSec, the thinking behind Jemurai, and why OWASP’s community appealed to him. The technical discussion compares Glue with Gauntlt and DefectDojo, examines integrations and extensibility, and considers how open-source projects can work together. Matt closes with a straightforward way for an individual developer to try Glue. Throughout, the focus is on connecting security work to engineering habits and making automation produce information people can act on.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Matt Konda:
→ Matt Konda on LinkedIn
→ OWASP Glue source code
Mentioned in this episode:
→ Gauntlt
→ OWASP DefectDojo
→ Brakeman
→ ZAP
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Connecting security tools with Matt Konda
01:09 From software development into security
04:34 Bridging the gap with development teams
08:55 The story behind Jemurai
10:34 Tools, processes, and useful security signals
13:33 Finding a community in OWASP
17:08 Why OWASP Glue was created
19:52 Comparing Glue with Gauntlt and adding tools
26:01 How Glue relates to DefectDojo
29:48 Improving commercial tool integrations
31:59 The easiest way to start using Glue
34:47 Final thoughts
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.